Live data from Hacker News

A board member's perspective of the RubyGems controversy

apiguy.substack.com

41–50 of 175 posts

Re: A board member's perspective of the RubyGems controversy

#41

Earlier quoted context omitted.

[flagged]

He is claiming that Ruby Central has the authority. True or not, that claim is not consistent with a coup. You seem to be catastrophizing and constructing misleading quotes, including inverting his words, not because his claim is not true but because of how he communicated it and the impact of it.

My point is that he chose to communicate the way he did; it is poorly thought out and extremely difficult to accept as an explanation.

Objective tests you yourself can perform.

1) How much of the publication talks about himself? Why is that relevant?

2) How much does it directly provide links, context, history? Can you find the opposing point of view directly linked from it, or is it omitted?

3) From reading the content, does this person represent the board, or not? Do they make any conflicting claims that are difficult to both be true at the same time?

4) A coup d'etat is a "a sudden, violent, and unlawful seizure of power from a government"

Were the people who lost access acting as a governing body? Was the loss of access sudden and unexpected? Did the loss of access follow any of the rules of the governing group? Did the loss of access harm individuals?

With the answers to the above, reflect on the following:

Why would someone write about themselves, their experience, etc for 6 paragraphs? Would you say it is clear they have only been appointed since Jan 2025? Or are they trying to establish themselves as an authority? If they are not attempting to appeal to authority, why is it relevant?

Did they actually apologise? If so, to who? Is it specific? Does it clearly articulate what the person did, admit fault, recognise harm? Or is there downplaying of impact, vague language, downplaying of involvement?

Does it characterise the contrary point of view in a way that trivial uses the concerns? Are the conversations "emotional" or is it implied the people experiencing the negative act are? Is the author emotional?

If you were the person or people affected, would you accept this explanation? If you were the person taking these actions, would you explain why like this? Why or why not?

I strongly encourage you to do this exercise, putting aside feelings or initial responses even if you think I am wrong.

Re: A board member's perspective of the RubyGems controversy

#42

The only reason why Ruby and other open source projects survive is because large companies can trust them to do the right thing. Given the critical nature of the supply chain attacks, what the board did was 100% right. Like he said, some people's egos got hurt but if no one can trust the maintainers, then Ruby has no future in the industry and it will die quickly. This is basically like fixing technical debt. It's pa…

The ego is what created the software. If you say f the ego, youre saying you want new maintainers

Re: A board member's perspective of the RubyGems controversy

#43
For any company that wants to secure and maintain critical source infrastructure for a language, community/maintainer relations is a fundamental responsibility. It is not to be waved away with quasi-candid admissions that you're just too small a team, too technical, etc. Even if this board member is being totally sincere about his feelings for Ruby and its community, it changes little.

> Some of those companies specifically pay Ruby Central to ensure the security and stability of that part of the supply chain, but then discovered that people with no active affiliation or agreement in place had top level privileges to some of this critical infrastructure.

This is the most candid bit of the article.

RubyCentral seems to have screwed up. The sense I get after reading this paragraph is that RC's non-apologies about poor communication are smoke. Why did they have to move this quickly/silently? Well...

If you are taking money from businesses in exchange for certain assurances about the security/soundness of RubyGems, you have a responsibility the minute pen leaves paper to KYC(ontributors). Not when there's suddenly a fire, or when your clients notice.

By all appearances, RC was negligent, if not necessarily in the legal sense. They were highly reactive in response to a problem they should have been across already, and they have paid for it with a chunk of the Ruby community's trust.

To now retcon this action as poorly-communicated but ultimately noble and security-minded does not sit very well.

Re: A board member's perspective of the RubyGems controversy

#44
This is a reasonable perspective but leaves a lot of unanswered questions and creates more questions. Who is the funder threatening to pull funding and why were they not more collaborative or flexible with Ruby Central? Did they know that this is how their request would be handled?

How much information and what information did Board members have when making their votes?

One thing that hasn’t been addressed is who was responsible for communications and implementation of this. It says here that the Director of Open Source did what the Board asked of him. Outside of the Board, which as stated here were heads down and trying to problem solve, Ruby Central’s website also shows a staff of several non-technical employees. Prominently, there is an Executive Director with a background in communications and non profit work per their LinkedIn. Where was this Executive Director and the other staff members during this? Were they involved with decision making and communication around this? How involved was the Board of Directors in implementation after the decision was made? It is a hollow statement to say they are just technical people trying to problem solve when there appears to be a whole team of non-technical staff members and an executive specializing in communications. Something clearly went wrong here and there are a lot of missing pieces around what happened after the vote took place. Most of this could have been mitigated with standard processes and simply communicating to maintainers and the community.

Re: A board member's perspective of the RubyGems controversy

#45
post #13

This story is missing any context around what occurred. The only thing I was able to find was by searching, and I came to this PDF statement. https://pup-e.com/goodbye-rubygems.pdf > On September 9th, with no warning or communication, a RubyGems maintainer unilaterally: > renamed the “RubyGems” GitHub enterprise to “Ruby Central”, > added non-maintainer Marty Haught of Ruby Central, and > removed every other maintain…

I found this helpful in explaining what's happened: https://www.theregister.com/2025/09/22/ruby_central_rubygems... Sounds like they made some really big changes and put zero effort into communicating to people who've spent 10+ years working on the project.

Thanks - that was helpful indeed. From there, I also found the linked post by Tekin Süleyman ( https://tekin.co.uk/2025/09/the-ruby-community-has-a-dhh-pro... ) to be informative.

Re: A board member's perspective of the RubyGems controversy

#46
post #15

I don't know more about the controversy than what's explained here, but, reading between the lines, it sounds like companies want Ruby Central to operate more like a for-profit company, where people carry out defined tasks in exchange for getting paid, than like a jury or the American Medical Association, where people do what seems best to them in exchange for a harder-to-define sense of collective social obligation.…

> reading between the lines, it sounds like companies want Ruby Central to operate more like a for-profit company, where people carry out defined tasks in exchange for getting paid, than like a jury or the American Medical Association, where people do what seems best to them in exchange for a harder-to-define sense of collective social obligation.

There was a funding agreement which imposed obligations upon the operators. Those obligations were to be sure that supply chain attacks were reasonably secured against. The volunteers didn’t have to sign that agreement - they chose to and received consideration for their decision to sign.

Licensing terms don’t change the underlying mechanism of a contract and the message is even easier. If your organization cannot abide by the terms of a contract, don’t sign it.

Re: A board member's perspective of the RubyGems controversy

#47
post #10

I'm truly hoping for a reasonable resolution on all sides for this situation. IMO Ruby is too small, and shrinking compared to Python and JS/TS especially in the AI era, to be able to afford any splintering of efforts.

Agreed. I wish the communications would move away from FUD that could scare people away from using Ruby when things are already splintered. A more honest and transparent accounting of what really happened is necessary.

Re: A board member's perspective of the RubyGems controversy

#48
post #13

This story is missing any context around what occurred. The only thing I was able to find was by searching, and I came to this PDF statement. https://pup-e.com/goodbye-rubygems.pdf > On September 9th, with no warning or communication, a RubyGems maintainer unilaterally: > renamed the “RubyGems” GitHub enterprise to “Ruby Central”, > added non-maintainer Marty Haught of Ruby Central, and > removed every other maintain…

How you can tell this is all lies from the board is simple:

> How do you tell someone that has had commit and admin access to critical infrastructure long after that need has expired that you need to revoke that access without upsetting them?

The first thing is they didn't tell them. The second bit is simple:

"Hi [x], I'm sure you've seen the news about npm. Given supply chain attacks directed at them and the one recently foiled against the python folks, we're [doing fill in here], including reducing permissions. [More info here.] Further updates as soon as we have them."

That email takes 10 minutes to write and send.

Re: A board member's perspective of the RubyGems controversy

#49
post #40

Locking out a guy like David Rodriguez (the main person I see doing bundler commits) in a dramatic fashion just seems like absolute craziness. I can't fathom doing it without a very good reason, which has yet to be revealed if it exists.

Does “lest we lose critical funding because we don’t have proper agreements with our committers” not cut it as a reason for you? Genuinely curious, it seems like a reasonable explanation assuming it’s true.

It does not, for me.

Given that access was cut, then restored, then cut again, then days, then someone finally says "hey were were going to lose critical funding" makes it seem like a post-facto excuse for a hostile takeover.

And the whole "oh, well, we're bad at comms" makes it sound even worse!

Which is the whole crux of the issue. At no point in any of this did Ruby Central do anything reasonable. The they tried to explain that their unreasonable actions were reasonable, if you only knew the things they knew, which they were for some reason unable to tell people until just now.

Could it be true? Sure, absolutely.

Does it seem reasonable at the moment? Hell no.

Re: A board member's perspective of the RubyGems controversy

#50
post #6

> I can't speak for the board or the Ruby Central staff. But I know them and they are like me. They do this because they love Ruby and our community. I'm certain of that. I don't know how to reconcile 'they love Ruby and our community' with moves that are actively hostile to the community.

> [do what we did], or lose the funding that we use to keep those things online and going

Seems pretty clear-cut to me.

Post reply on HN